I'm reading Max Hillebrand's Praxeology of Privacy (#1489281) and would very much enjoy the Stackers' opinions about the things inside. Your commentary is welcome even if you don't have time to read the book. Part I - #1501602, Part II - #1507762, Part III - #1515488
I liked how Hillebrand sets the stage for this part in Chapter 10 using Rothbard's three-level categorization of interventions:
- Governments can exert force on you directly by telling you to do something (eg conscription, compulsory schooling)
- Governments can force themselves into an exchange with you (eg. taxation, eminent domain)
- Governments can dictate the terms of transactions to which they are not a party (eg. licensure, price controls)
Most of this part of the book focuses on how governments coming to use the third category of intervention to control their citizens. Encryption gives citizens tools that can be used to effectively resist the first two categories of state intervention, but with the use of wide-spread, comprehensive surveillance, states can intervene in people's lives even when they are equipped with strong cryptography. And the state has been building their surveillance apparatus for some time:
The Bank Secrecy Act of 1970 imposed reporting requirements that revealed gaps. The Money Laundering Control Act of 1986 closed some gaps by making the underlying conduct a predicate offense and adding Suspicious Activity Reports to the Currency Transaction Report regime. The USA PATRIOT Act of 2001 extended the regime to non-bank money-service businesses whose growth had been one of the revealed gaps. The 2016 Customer Due Diligence rule required banks to identify beneficial owners behind legal-entity customers, closing the gap that shell companies had opened. The FATF Travel Rule extension to virtual-asset service providers in 2019 and its global rollout through 2024 closed the gap that non-custodial crypto transfers had opened.
The is a brief but interesting examination of whether data extraction is a market failure (is the the vast amount of observable data we produce every day and which gets used against us a sort of market externality for which markets do not account?) -- Hillebrand's answer seems to be that it is not, but it felt a little flat to me: well, it never was a free market in the first place isn't a very satisfying. I do wonder how markets can effectively price the value of data collected by third parties that try to observe me (and everyone else) and sell the data en masse to governments or thugs or corporations.
By the time we get to Chapter 12, the feeling seems to be that basically you don't have any privacy anymore: you leave so many digital records moving through the world we have created, and these records are mostly collected by private entities who can and do sell them on the open market. Hillebrand seriously challenges the value of the famous cypherpunk victories in the crypto wars in the face of mass meta data analysis by AI:
The book’s earlier argument was that privacy defense is cheaper than privacy offense, because encryption costs cents while breaking it costs billions. That argument holds for each unit of communication. The analytics stack does not attack individual units; it attacks aggregation. A million intercepted records are worth nothing if no analyst can read them. A million intercepted records fed to a model are worth everything, because the model extracts the patterns at a cost per query that approaches zero. The cost asymmetry that once favored defense has been partly offset at the aggregation layer.
The target of defense has moved. Encrypting content remains essential, but it is no longer sufficient. What must also be protected is the metadata that the model uses to build patterns when content is unavailable: timing, social graph, location, device identifier, and frequency. The model is a metadata analyst first and a content analyst only when metadata fails.
Hillebrand develops the theme through many examples, most of which are very disheartening. Even the best case scenarios are pretty bad:
Ring, the Amazon-owned home-camera product, illustrates the partial-retreat variant. From 2018 through 2024 the Neighbors app allowed police to solicit footage directly from Ring owners through a “Request for Assistance” tool. Public opposition to the surveillance implications led Amazon to remove the tool in January 2024. The infrastructure did not disappear. Police now obtain Ring footage through warrants served on Amazon or through owner consent, which is the older process with a higher transaction cost. Public attention can raise the price of a surveillance channel without closing it.
And he also makes a very interesting distinction between data we have the ability to change (like passwords and usernames) and biometric data that is unalterable.
The practical consequence is that a database breach of biometric or genetic data is not a recoverable condition. The breach of a credential database means “rotate all credentials now”; the breach of a biometric database means “the identifier is now permanently known to the adversary, and every future use of that identifier must be assumed to be observable by the adversary.” The exposure extends across the lifetime of the person.
So, if this part of The Praxeology of Privacy should be summarized, it is with this statement:
The case was dropped without charges, but it established the template for Crypto Wars conflicts: the government asserts control authority; technologists route around restrictions; the restrictions prove unenforceable; formal policy catches up with technical reality
While Hillebrand doesn't exactly come out and say it, the main point I took away from Part IV is that there really isn't any hope that data, once available, will not be used against you. The only solution is preventing your data from leaking or proving its use is without value. I will be interested to see if that is the approach he takes through the rest of the book: we can't expect cultures, norms, or even laws to defend us -- we need impossibilities.
I continue to find excellent rabbitholes in the footnotes:
- Institute for Justice, Policing for Profit: The Abuse of Civil Asset Forfeiture, 3rd ed. (2020)
- Paul Ohm, “The Fourth Amendment in a World Without Privacy,” Mississippi Law Journal 81 (2012): 1309
- Orin S. Kerr, “The Case for the Third-Party Doctrine,” Michigan Law Review 107 (2009)
- Neil Postman, Technopoly: The Surrender of Culture to Technology (New York: Alfred A. Knopf, 1992)
- Jeff Kosseff, The Twenty-Six Words That Created the Internet (Ithaca, NY: Cornell University Press, 2019)
- Frédéric Bastiat, “Ce qu’on voit et ce qu’on ne voit pas” (1850), translated as “That Which Is Seen, and That Which Is Not Seen,” in Selected Essays on Political Economy
- Byron Tau, Means of Control: How the Hidden Alliance of Tech and Government is Creating a New American Surveillance State (Crown, 2024)
- Kashmir Hill, Your Face Belongs to Us: A Secretive Startup’s Quest to End Privacy as We Know It (Random House, 2023)
Right, that doesn't actually imply that it wouldn't be a problem under market dynamics. What I gather is the relevant point is that governments are requiring some of this data collection by private firms, which does imply that the firms don't perceive that collection as being worth the cost.
So, absent those state regulations, there would likely be competition from firms (that are currently excluded from entry) catering to privacy concerns.
It is very messy. For instance, cell phone location data -- I'm not the best at the technical side, but I think there is not any cell phone service that offers connection without it creating something that could be used to track the location of the phone. They can claim they delete it, but this is futile in my mind. It's hard to imagine any major carrier not recognizing that such location data is valuable. Is the best the market can do is incentivize a company that says "we won't sell this data"?
In the case of something like flock cameras, city's seem to have an incentive to put them up. If that's not a good example, Ring cameras might be: each user wants to use them for their own personal use, but the incentives might be such that Ring offers a discount if you let them sell aggregate data to police departments (or even whoever wants it). Will the market produce a privacy preserving option?
Evidence seems to be that majority don't value privacy highly. If I opt out of the Ring network and pay extra for a closed circuit home camera, but all my neighbors go for the cheap "sell me out to the cops" Ring network, the market doesn't seem to be able to offer me a solution.
I can hear you saying: the market offers you a hone in a rural area...
Actually, I was going to say that you don't have a right to privacy while putting yourself in the view of others. Your neighbors' Ring cameras can only see what is visible from their property, which they have every right to see.
The relevant point is more that reducing the number of data points available to aggregators has a potentially large impact because it reduces the degrees of freedom available for statistical inference.
The direct effect of that is less confidence in the inferences made about you. The indirect knock-on effect is that, because the information about you is less reliable, the other data about you becomes less profitable and less of it will be collected.
Every step of the data collection and analysis process carries a cost. So raising those costs or reducing the benefits will lead to more privacy.
Private parts book club